Walter Ledger

The EU AI Act: What This New Rulebook Means for Your Website

EU AI Act

Author: Walter Ledger

I’ll be honest. When I first read about Regulation 2024/1689, better known as the EU AI Act, my eyes glazed over. Another regulation. Haven’t we only just got our heads around GDPR?

Then I looked at the calendar. The first rules that touch ordinary website owners started applying on 2 August 2026, and a week before that the whole timetable was torn up and rewritten. So if you read something about this last year and filed it under “deal with it later”, later has arrived and the dates you wrote down are wrong.

Here’s what’s happened, in plain English, and then the bit that actually applies to you. Which is smaller than you’d fear.

The thing nobody told you: the rules changed in July

The AI Act passed in 2024 with a staggered timetable. Bans first, then rules for the big underlying AI models, then the heavy obligations for so-called high-risk systems on 2 August 2026.

The problem was that Brussels wrote the deadlines before it wrote the instruction manual. The technical standards weren’t finished. Half the member states hadn’t appointed the authorities meant to police any of it. Businesses were being told to prove compliance against a rulebook that didn’t exist, which is a bit like being asked to sit an exam and then told the syllabus is still at the printers.

So the Commission proposed a fix, the Digital Omnibus on AI. It became Regulation (EU) 2026/1744, published on 24 July 2026 and in force from the 27th. They cut it fine deliberately, because the old deadline was days away.

This matters because nearly everything you’ll find online about AI Act deadlines was written before it happened.

This matters because almost every article you’ll find about AI Act deadlines was written before that happened.

Regulation 2024/1689, as amended July 2026

When each part of the AI Act actually bites

  1. 2 February 2025 In force

    The outright bans, and AI literacy

    Social scoring, emotion recognition at work and school, and scraping faces off the internet stopped being legal. The same date brought the duty to understand the AI you use.

  2. 2 August 2025 In force

    Rules for the big underlying models

    Obligations landed on the general purpose systems sitting underneath everything else.

  3. 2 August 2026 You are here

    Transparency

    Chatbots have to admit they are chatbots, and photoreal synthetic media has to be labelled. Cartoons and illustrations don’t count, and nothing published before today needs relabelling.

  4. 2 December 2026

    Grace period ends, and a new ban

    Tools already on the market run out of road on marking AI-generated content. AI built to produce non-consensual intimate images is outlawed.

  5. 2 August 2027

    Testing grounds open

    Every member state has to run at least one regulatory sandbox. A year later than originally promised.

  6. 2 December 2027

    High-risk systems, the standalone ones

    Screening job applicants, marking exams, scoring credit, gating essential services. This was meant to be August 2026. You have sixteen extra months.

  7. 2 August 2028

    High-risk systems built into products

    AI inside medical devices, machinery and other regulated kit. The last domino.

Dates reflect the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026.

What the Act is actually for

It isn’t a ban on AI and it isn’t an attempt to stop innovation. It’s a risk ladder.

At the top sit practices that are simply not allowed. Social scoring, where people get rated on their behaviour and treated differently as a result, and note that this ban isn’t limited to governments, which plenty of write-ups get wrong. Private companies can’t do it either. Also out: emotion recognition in workplaces and schools, scraping faces off the internet to build recognition databases, and real-time biometric identification in public by police, with narrow exceptions.

Below that are high-risk systems. Allowed, but heavily controlled. AI that screens job applicants, marks exams, decides who gets credit, or runs part of a hospital. Conformity assessments, documentation, logging, human oversight, demonstrable accuracy. That’s a genuine project, and it’s why the deadline moved.

Then limited-risk systems, which just have to be honest about themselves. That’s the tier most websites live in.

And at the bottom, minimal risk, where almost nothing is required. Spam filters, basic recommendation engines, autocorrect. The vast majority of what your site does.

The definition of an AI system is narrower than the headlines suggest, incidentally. It has to operate with some degree of autonomy and may adapt after deployment. A spreadsheet formula that does exactly what you told it every single time isn’t AI just because it’s clever.

The bit that’s just started: transparency

Chatbots first. If you’ve got one, users need to know they’re talking to software. Not buried in a privacy policy. Visible, at the point of contact. If it’s blindingly obvious from context you get some latitude, but I wouldn’t lean on it.

Now pictures, audio and video, where the advice online goes lazy. The rule is not “label all AI images”, it’s about deepfakes, and the Act means something specific by that word.

Three things have to be true at the same time. Miss any one of them and the labelling duty doesn’t apply to you.

Article 3(60) · all three must be true

Is your picture actually a deepfake?

Does it closely resemble its subject?

A high level of similarity, not a passing likeness.

and

Does that subject exist, or could it?

A real person, place or event, or one that could plausibly have existed.

and

Could someone take it for real?

Judged by your actual audience and what they expect to see.

Three yeses and it’s a deepfake. Label it, visibly, where people will see it. One no and it isn’t. No label needed.

How that plays out

No label

A cartoon illustration of somebody at a kitchen table. Nobody would mistake it for a photograph, so the third test fails.

Label it

A photoreal image of a person who doesn’t exist. Still caught. The person needn’t be real and you needn’t have meant to fool anyone.

Label it

A convincing shot of a street, a building or an event that looks like it happened. Same three tests, same answer.

No label

Anything you published before 2 August 2026. There is no duty to go back through your archive.

The obligation nobody mentions

Article 4. AI literacy.

It’s applied since February 2025, it covers everyone providing or using AI rather than just the high-risk crowd, and I’ve almost never seen it discussed. You have to take measures to give your staff and other relevant people a reasonable working understanding of the AI they’re using. The Omnibus softened the wording so you’re not guaranteeing any particular standard for any particular person, but the duty is still there.

For a one-person operation this is not onerous. It means knowing what your tools do, what they get wrong, and when not to trust them. For anyone with staff, it means an actual conversation and probably a note that you had it. That’s it. But it exists, and it touches practically every business in the EU.

So what does your website actually have to do?

Take stock first. Write down every AI system your site touches. The chatbot. The recommendation widget. The writing assistant. The spam filter. The bits your website builder and email platform bundle in without telling you, which is more of them than you’d think.

For each one, ask what it does to people. Does it decide something about them, or does it just tidy something up? Sorting spam is tidying. Screening job applicants is deciding. That distinction is more or less the whole Act in a sentence.

Then the easy wins. Label your chatbot today, because it’s one line of text.

Label photoreal synthetic media going forward, and leave your archive alone.

If you’re sifting job applications through your careers page, you’re in high-risk territory and you’ve got until December 2027, and you’ll need it.

If you’re relying on third-party tools, and you are, most of the burden sits with whoever built them. Not all of it. You have your own duties as a deployer, and “my supplier said it was fine” isn’t a defence anyone has ever won with. Ask your vendors what they’re doing about the AI Act and see whether the answer sounds like a plan or a press release.

On fines, size the risk properly. The famous 35 million euros or seven per cent of global turnover applies to the outright banned practices. Transparency breaches and most other failures top out at 15 million or three per cent, and misleading a regulator at 7.5 million or one per cent. Those are ceilings for the worst offenders among the largest companies, and regulators are specifically told to be proportionate with small businesses. Nobody is coming for your unlabelled chatbot with a seven-figure penalty. But proportionate is not the same word as ignored.

Where I’ve landed on all this

The AI Act isn’t the monster it was made out to be, and the July rewrite is a quiet admission that the original timetable was written by people who’d never had to comply with anything.

For most website owners the practical job is small. Label your chatbot. Label photoreal synthetic media from here on. Know what tools you’re using. Make sure whoever works with you understands the AI they’re touching. Keep an eye on your suppliers. That’s a morning’s work, not a compliance department.

If you’re doing something that genuinely affects people’s lives, screening candidates, scoring creditworthiness, marking exams, then yes, real work is coming and you’ve got until December 2027. Start now anyway. Sixteen months disappears faster than you think, and the standards you’ll need are still being written.

What I keep coming back to is that none of this is really about AI. It’s about whether the people affected by an automated decision get to know it was made, and get a way to argue with it. Strip out the article numbers and that’s what’s left. Hard to object to, even when the paperwork is annoying.

Have a look at your own site this week. Find the AI, label the bits that need it, put December 2027 in the diary. Then go and have a cup of tea, because that really is most of it.

Walter

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Post

ChatGPT memory feature

ChatGPT Remembers You Now. Do I Need to Worry About That?

I’ll be honest with you. The first time I heard ChatGPT could now remember our conversations, I thought of that neighbour everyone seems to have. The one who somehow knows …